CVE-2026-72191
Local NTFS3 driver flaw allows crafted NTFS image to trigger kernel OOB write and crash.
Is CVE-2026-72191 being exploited?
Not confirmed. CVE-2026-72191 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.68% probability of exploitation in the next 30 days.
How severe is CVE-2026-72191?
CVE-2026-72191 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72191?
Yes. A fix has been recorded for CVE-2026-72191. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72191 affect?
CVE-2026-72191 affects Linux kernel ntfs3 filesystem driver, Systems auto-mounting NTFS (USB, loopback, removable media). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72191?
Apply vendor kernel/ntfs3 patch immediately or disable ntfs3/auto-mount for untrusted media.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker mounting an attacker-controlled NTFS image can trigger an out-of-bounds kernel write, causing memory corruption, kernel panic and possible privilege escalation.
Immediate action required
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < 8e4ba5a38c155bb3c1c11e63cd285b178cdb099e
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < 4c2f648139a0a86f4486170f72e24fedd4fae74e
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < b232eb5c9fe11ec2368e9b565db69c724c35fbd2
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < 7bf74e6baf810fe325f111996496c678fc6e244f
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < f3624cc069195001c88df7a291af215f2133ff2c
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < 1758a564b6ebe7f4a82f23c9851d1cae15549457
- affected>= 82cae269cfa953032fbb8980a7d554d60fb00b17 and < f1df9d771df47aa40de6d70949c28720ae1e430d
- affected5.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.